Impact
Oracle Reports Developer 14.1.2.0.0 contains a critical authentication and authorization bypass flaw that allows an unauthenticated attacker with network access to the CORBA service to send crafted requests and execute arbitrary code. The vulnerability is rated CVSS 3.1 base score 9.8, illustrating substantial confidentiality, integrity, and availability impacts. Exploitation enables full takeover of the Reports Developer instance, allowing the attacker to run commands with the permissions of the application process.
Affected Systems
The flaw affects Oracle Corporation's Oracle Reports Developer version 14.1.2.0.0. Any deployment exposing the CORBA interface to outside networks is susceptible. No other product versions are listed as vulnerable, and the vulnerability is specifically tied to the Security and Authentication component of Oracle Fusion Middleware.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability that the vulnerability will be exploited by attackers at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the CVSS rating underscores that a successful exploit would result in remote code execution and complete compromise of the application, potentially serving as a foothold for further attacks. Attackers are expected to use unauthenticated CORBA requests to trigger the flaw, so restricting or disabling external access to the CORBA service significantly reduces the attack surface.
OpenCVE Enrichment